Basis: Certvia dev@a48c5fb als Fundament für Craftvia
Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,175 @@
|
||||
# Information Security Policy
|
||||
|
||||
| Document information | Value |
|
||||
|-----------------------|------|
|
||||
| Document type | Policy |
|
||||
| Scope | {{ISMS_SCOPE}} |
|
||||
| Organisation | {{ORG_NAME}} |
|
||||
| Responsible | {{ROLE_ISB}} |
|
||||
| Approved by | {{ROLE_MANAGEMENT}} |
|
||||
| Version | {{DOC_VERSION}} |
|
||||
| Date | {{DOC_DATE}} |
|
||||
| Status | {{DOC_STATUS}} |
|
||||
|
||||
## 1. Purpose
|
||||
|
||||
<!-- REQ 1.1.1-M1 -->
|
||||
This information security policy describes the fundamental requirements, objectives and responsibilities of {{ORG_NAME}} for protecting information, IT systems, business processes and supporting assets. The information security requirements are defined, documented and aligned with the objectives of {{ORG_NAME}}.
|
||||
|
||||
The objective is to ensure an appropriate level of information security and to meet the requirements of VDA ISA 2027 in the area of information security.
|
||||
|
||||
## 2. Scope
|
||||
|
||||
This policy applies to the defined ISMS scope:
|
||||
|
||||
{{ISMS_SCOPE_DESCRIPTION}}
|
||||
|
||||
It applies to:
|
||||
|
||||
- all employees within the scope,
|
||||
- managers,
|
||||
- external service providers, insofar as they have access to the organisation's information, systems or processes,
|
||||
- relevant IT systems, information, applications, sites and business processes within the ISMS scope.
|
||||
|
||||
## 3. Information security objectives
|
||||
|
||||
<!-- REQ 1.1.1-M3 -->
|
||||
The policy states the objectives and the importance of information security. Through the ISMS, the organisation pursues in particular the following objectives:
|
||||
|
||||
- protection of confidential information against unauthorised access,
|
||||
- ensuring the integrity of information and systems,
|
||||
- ensuring the availability of business-critical information, systems and services,
|
||||
- compliance with legal, regulatory and contractual requirements,
|
||||
- appropriate protection of customer information, personal data, trade secrets and other information requiring protection,
|
||||
- structured identification, assessment and treatment of information security risks,
|
||||
- continual improvement of information security.
|
||||
|
||||
## 4. Information security principles
|
||||
|
||||
Information security is based on the following principles:
|
||||
|
||||
### 4.1 Risk orientation
|
||||
Information security measures are planned, implemented, reviewed and improved in a risk-oriented manner. Risks are assessed and tracked in the ISMS tool in use ({{TOOL_NAME}}) (see {{LINK:R03}}).
|
||||
|
||||
### 4.2 Appropriateness
|
||||
Protective measures must be appropriate to the protection needs of the information, systems and processes. Confidentiality, integrity and availability are taken into account.
|
||||
|
||||
### 4.3 Responsibility
|
||||
Information security is a shared responsibility of all employees. {{ROLE_MANAGEMENT}} holds overall responsibility for the ISMS.
|
||||
|
||||
### 4.4 Traceability
|
||||
Decisions, assessments, approvals and material measures relating to information security must be documented in a traceable manner.
|
||||
|
||||
### 4.5 Continual improvement
|
||||
The ISMS is reviewed regularly and adjusted where necessary. Findings from audits, incidents, risks, changes and management reviews feed into the improvement.
|
||||
|
||||
## 5. Information security requirements
|
||||
|
||||
<!-- REQ 1.1.1-S1 -->
|
||||
{{#if FLAG_INCLUDE_SHOULD}}The information security requirements are based on the strategy of {{ORG_NAME}}; legal and contractual requirements are taken into account. {{/if}}The organisation determines and documents information security requirements on the basis of:
|
||||
|
||||
- legal and regulatory requirements,
|
||||
- contractual requirements, in particular from customers and partners,
|
||||
- requirements from the VDA ISA,
|
||||
- internal business requirements,
|
||||
- results of risk analyses,
|
||||
- protection needs of information, processes and IT systems,
|
||||
- requirements from projects, changes and external IT services.
|
||||
|
||||
The relevant requirements in each case are taken into account in the ISMS and implemented through suitable policies, processes, technical measures and evidence.
|
||||
|
||||
## 6. Roles and responsibilities
|
||||
|
||||
The organisation defines roles and responsibilities for information security. These include at least:
|
||||
|
||||
| Role | Fundamental responsibility |
|
||||
|-------|------------------------------|
|
||||
| {{ROLE_MANAGEMENT}} | Overall responsibility, approval of the information security policy, provision of appropriate resources |
|
||||
| {{ROLE_ISB}} | Steering, maintenance and further development of the ISMS |
|
||||
| Managers | Implementation of the requirements within their respective area of responsibility |
|
||||
| {{ROLE_IT_LEAD}} | Implementation of technical and organisational security measures in the IT area |
|
||||
| Asset owners / process owners | Assessment and maintenance of relevant information, processes and assets in the ISMS tool |
|
||||
| Employees | Compliance with the policies and reporting of security events |
|
||||
| External service providers | Compliance with contractually agreed security requirements |
|
||||
|
||||
The specific assignment of roles and responsibilities is maintained in the ISMS tool ({{TOOL_NAME}}) or in a supplementary role matrix (see also {{LINK:R01}}).
|
||||
|
||||
## 7. Binding nature
|
||||
|
||||
<!-- REQ 1.1.1-M2 -->
|
||||
<!-- REQ 1.1.1-S2 -->
|
||||
This policy is approved by {{ROLE_MANAGEMENT}} and is binding for all affected persons within the scope. {{#if FLAG_INCLUDE_SHOULD}}Violations of information security requirements may lead to organisational, employment-law or contractual measures. {{/if}}All employees are obliged to:
|
||||
|
||||
- comply with the applicable information security policies,
|
||||
- handle information requiring protection appropriately,
|
||||
- report security events or suspected cases without delay,
|
||||
- use only approved systems, applications and services,
|
||||
- report identified vulnerabilities or risks to the responsible body.
|
||||
|
||||
## 8. Publication and communication
|
||||
|
||||
<!-- REQ 1.1.1-M4 -->
|
||||
<!-- REQ 1.1.1-M5 -->
|
||||
The information security policy is made known to the relevant persons in a suitable form; employees and affected external partners are informed about relevant changes. This can be done via:
|
||||
|
||||
- publication in the ISMS tool ({{TOOL_NAME}}),
|
||||
- internal wiki or document management system,
|
||||
- onboarding process,
|
||||
- awareness training (see {{LINK:R05}}),
|
||||
- direct communication to the affected target groups.
|
||||
|
||||
## 9. Review and update
|
||||
|
||||
<!-- REQ 1.1.1-S4 -->
|
||||
This policy is reviewed regularly, but at least:
|
||||
|
||||
- {{REVIEW_CYCLE}},
|
||||
- upon material changes to the ISMS scope,
|
||||
- upon material organisational or technical changes,
|
||||
- in the event of relevant security incidents,
|
||||
- upon new or changed regulatory, legal or contractual requirements.
|
||||
|
||||
Changes are documented and approved by {{ROLE_MANAGEMENT}}.
|
||||
|
||||
## 10. Evidence
|
||||
|
||||
The evidence for the implementation of this policy is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
|
||||
|
||||
## 11. Related documents
|
||||
|
||||
<!-- REQ 1.1.1-S3 -->
|
||||
Further topic-specific security policies (R01–R14) are established and coordinated with one another.
|
||||
|
||||
- Technical security baseline: {{LINK:BASELINE}}
|
||||
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
|
||||
- Evidence register: {{LINK:NACHWEISREGISTER}}
|
||||
- ISMS organisation and roles: {{LINK:R01}}
|
||||
- All thematic policies: {{LINK:R01}} … {{LINK:R14}}
|
||||
|
||||
<!-- Das Mapping der Anforderungen (REQ/IMPL) zu VDA-ISA-Controls ist in mapping.json hinterlegt und wird vom Tool über die Hidden-Anker aufgelöst. Im Lesemodus nicht sichtbar. -->
|
||||
|
||||
<!-- FW:ISO-SECTION-START -->
|
||||
{{#if FLAG_FW_ISO27001}}
|
||||
|
||||
## Annex A — Information security policy, objectives and communication
|
||||
|
||||
*Requirement reference:* ISO/IEC 27001 5.2, 6.2, 7.4, A.5.1
|
||||
|
||||
**Requirement**
|
||||
|
||||
<!-- REQ 5.2-1 -->
|
||||
- **[ISO 5.2]** An information security policy is established that fits the organisation, sets objectives, commits to meeting requirements and to continual improvement, and is communicated and available.
|
||||
<!-- REQ 6.2-1 -->
|
||||
- **[ISO 6.2]** Information security objectives are established for relevant functions and levels, and their achievement is planned.
|
||||
<!-- REQ 7.4-1 -->
|
||||
- **[ISO 7.4]** The internal and external communications relevant to the ISMS are determined.
|
||||
<!-- REQ A.5.1-1 -->
|
||||
- **[ISO A.5.1]** The information security policy and topic-specific policies are defined, approved by management, published, communicated, acknowledged and reviewed at planned intervals.
|
||||
|
||||
**Implementation at {{ORG_NAME}}**
|
||||
|
||||
<!-- IMPL ISO-LEITLINIE -->
|
||||
This policy is approved by {{ROLE_MANAGEMENT}}, published in {{TOOL_NAME}} and made known to all staff and relevant third parties; acknowledgement is recorded per version. It is reviewed at least {{POLICY_REVIEW_CYCLE}} and upon significant change (BL-GOV-03). The thematic policies and the procedures elaborate it and follow the same approval and review cycle. The information security objectives are stated in measurable terms and held in {{TOOL_NAME}} with target value, responsible role and due date; their achievement is evaluated {{MGMT_REVIEW_CYCLE}}. For internal and external communication on information security it is defined what is communicated, when, with whom and by whom; the central point of contact is {{ROLE_ISB}}.
|
||||
|
||||
{{/if}}
|
||||
<!-- FW:ISO-SECTION-END -->
|
||||
Reference in New Issue
Block a user